CVE-2021-38009: Inappropriate implementation in cache
Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38009.
What is the severity of CVE-2021-38009?
The severity of CVE-2021-38009 is medium, with a severity value of 6.5.
Which software versions are affected by CVE-2021-38009?
Google Chrome versions prior to 96.0.4664.45, Fedora 34, Debian Linux 10.0, Debian Linux 11.0, and Chromium version 90.0.4430.212-1~deb10u1 are affected by CVE-2021-38009.
How can a remote attacker exploit CVE-2021-38009?
A remote attacker can exploit CVE-2021-38009 by leveraging an inappropriate implementation in the cache in Google Chrome prior to 96.0.4664.45 to leak cross-origin data via a crafted HTML page.
Where can I find more information about CVE-2021-38009?
You can find more information about CVE-2021-38009 in the references provided: https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html, https://crbug.com/1260649, https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3W46HRT2UVHWSLZB6JZHQF6JNQWKV744/